Tools
Ten Factor Governance is not a product: the factors name properties of operable governance. This section covers some tools and standards that already express those properties which have been referenced in the descriptions of the factors.
It is not meant to be an exhaustive list - just a way to help orient the reader whilst understanding the factors.
Each page summarises what the tool is for and which factors it helps and provides a brief jumping-off point for further investigation.
This is not a recommendation - you may find alternatives to these tools which are better suited to your purposes or context, or you may find you don't need a tool at all to achieve your governance objectives: the best software is often no software at all.
AWS Config
AWS service for recording resource configuration, relationships and compliance over time.
Backstage
An open platform for building developer portals with a typed software catalogue, owners and relations.
Cedar
A policy language for authorisation decisions over principals, actions, resources and context.
CI/CD
Continuous integration and continuous delivery—automated pipelines that validate change and promote it through environments.
Cloud Asset Inventory
Google Cloud inventory of assets and relationships across projects and services.
Common Cloud Controls
An open FINOS standard for technology-agnostic cloud security, resiliency and compliance controls with machine-verifiable assessments.
CycloneDX
An OWASP standard for software bills of materials (SBOMs) and related supply-chain inventory formats.
DMN
OMG Decision Model and Notation for executable decision tables and decision requirements diagrams.
Flux
GitOps toolkit for Kubernetes that reconciles desired state and can gate changes with policy.
Gatekeeper
Kubernetes-native policy controller built on OPA, with admission enforcement and audit modes.
Gemara
An activity-centred GRC model with typed, linkable governance artifacts across definition, activity and measurement layers.
GitHub CODEOWNERS
GitHub feature that maps paths to required reviewers so changes have named owners.
grc.store
A registry for publishing, distributing and installing governance artefacts such as control catalogues and related packages.
in-toto
A framework for cryptographically verifying software supply-chain steps via link metadata and layouts.
Kubernetes
Container orchestration platform whose admission controllers intercept API requests before persistence.
NIST C-SCRM
NIST SP 800-161 guidance on cyber supply-chain risk management for acquiring and using ICT products.
Open Policy Agent
A general-purpose policy engine (Rego) that evaluates structured input and returns structured decisions.
OpenSSF Scorecard
Automated security health metrics for open-source projects, produced as machine-readable results.
OSCAL
NIST Open Security Controls Assessment Language for machine-readable controls, profiles and assessment results.
ServiceNow CMDB
An enterprise configuration-management database for IT assets, CIs and relationship maps.
SLSA
Supply-chain Levels for Software Artifacts—provenance requirements that show how an artefact was built.
XACML
OASIS standard for attribute-based access control with request/response evaluation and obligations.